How can I redirect the event viewer files?
We are about to implement a client solution wherein each client PC loads an
image from an image server on each boot-up. Since all the event viewer and log files are lost when
the operating system reloads, we are unable to perform forensic troubleshooting. Is there a way to
redirect the event viewer files to another partition or network share?
Microsoft's Audit Collection Service (ACS) has been in beta for quite some time now, so your
current best bets would be either to create a scheduled job on each workstation that dumps the
system logs and copies them to a central location, or else to use a third-party utility for Event
Log collection such as DorianSoft's Event Archiver: (http://www.doriansoft.com/totalsolution/
When deciding on a solution, remember that Event Log data is critical information that should
not be transmitted or stored in an insecure fashion; be sure that the security of your log data
both in transit and in storage is a key factor in your decision-making process.
This was first published in November 2005